CVE-2021-3960

HIGH

Bitdefender GravityZone < 3.3.8.272 - Remote Code Execution via UpdateServer Path Traversal

Title source: llm
STIX 2.1

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior to 3.3.8.272

Scores

CVSS v3 7.1
EPSS 0.0031
EPSS Percentile 22.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
bitdefender/gravityzone < 3.3.8.272
Published Dec 16, 2021
Tracked Since Feb 18, 2026